Re: Fwd: New Version Notification for draft-ietf-uta-xmpp-03.txt
Peter Saint-Andre - &yet <[email protected]> Thu, 13 Nov 2014 16:08:51 -0700
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <[email protected]> |
Hi Dave, thanks for the feedback. On 11/12/14, 4:47 AM, Dave Cridland wrote: > Lightning review: > > 1) §3.3 - I don't understand why session tickets would be bad compared > to session ids? I freely admit that I don't understand the effective difference between session IDs and session tickets for XMPP (or for TLS session resumption in general). To my meager brain, the differences are not explained well in the RFCs. Enlightenment would be appreciated. :-) > 2) Should there be a discussion about recommended SAN types? RFC 6120 > currently says the only MTI is xmppAddr; RFC 6125 gives no MTI as I > understand it. This is covered in §13.7.1.2.1 of RFC 6120. Perhaps a pointer to that section would be helpful? > 3) If so, should we discuss wildcard resolution? Or not? RFC 5280 says > wildcard resolution is within the scope of the application rather than > TLS/PKIX itself. That's also covered in the aforementioned section of RFC 6120. However, do we feel that it's time to revisit the text there? (BTW, Jeff Hodges and I tried to kill off wildcard certs entirely in RFC 6125 but weren't successful.) > 4) Finally, there's two different protocols in XMPP - C2S and S2S. It > might be good to explicitly note the different requirements on these > (the draft says C2S clients MUST authenticate servers, for example). And it doesn't say that servers need to authenticate peer servers over s2s, which implies that unauthenticated s2s connections are allowed. This is consistent with current practice. Are you suggesting that we change the recommendation (e.g., SHOULD or MUST authenticate for s2s) or at least make it explicit that unauthenticated s2s connections are allowed? Peter -- Peter Saint-Andre https://andyet.com/ _______________________________________________ xmpp mailing list [email protected] https://www.ietf.org/mailman/listinfo/xmpp